CVE Feed

    Dashboard / CVE

    9.2
    Critical

    CVE-2026-22098

    Last Modified: 13 Jul 2026

    Various sensitive information such as passwords and charging card UIDs are written to log files.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-22097

    Last Modified: 13 Jul 2026

    The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.

    Published: 13 Jul 2026
    8.7
    High

    CVE-2026-22099

    Last Modified: 13 Jul 2026

    The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-22102

    Last Modified: 13 Jul 2026

    A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification. This can be used to cause a denial of service by overwriting system files, or remote-code-execution by overwriting shell-scripts which execution can be triggered through other means.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-22096

    Last Modified: 13 Jul 2026

    The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.

    Published: 13 Jul 2026
    8.6
    High

    CVE-2026-22100

    Last Modified: 13 Jul 2026

    The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-22095

    Last Modified: 13 Jul 2026

    The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

    Published: 13 Jul 2026
    9.5
    Critical

    CVE-2026-22093

    Last Modified: 13 Jul 2026

    The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted using RC4 with a hardcoded key, which allows an attacker to gain access to the communication. Part of this communication involves access codes to charging stations. This issue affects EVbee Service: v1.4.101.00.

    Published: 13 Jul 2026
    9.1
    Critical

    CVE-2026-41041

    Last Modified: 13 Jul 2026

    URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-49876

    Last Modified: 13 Jul 2026

    Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 through 1.2.1. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

    Published: 13 Jul 2026
    7.4
    High

    CVE-2026-15548

    Last Modified: 15 Jul 2026

    A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to stack-based buffer overflow. The attack is possible to be carried out remotely. This project is superseded by FreshTomato.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-61985

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-61977

    Last Modified: 13 Jul 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-61983

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-61976

    Last Modified: 13 Jul 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.

    Published: 13 Jul 2026
    5.3
    Medium

    CVE-2026-61975

    Last Modified: 13 Jul 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.

    Published: 13 Jul 2026
    2.7
    Low

    CVE-2026-61971

    Last Modified: 13 Jul 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-picture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Profile Picture: from n/a through <= 2.6.3.

    Published: 13 Jul 2026
    4.9
    Medium

    CVE-2026-61970

    Last Modified: 13 Jul 2026

    Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbnail allows Server Side Request Forgery.This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through <= 5.0.4.

    Published: 13 Jul 2026
    5.4
    Medium

    CVE-2026-61968

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.

    Published: 13 Jul 2026
    5.4
    Medium

    CVE-2026-61958

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-61956

    Last Modified: 13 Jul 2026

    Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام &#8211; همگام سازی ووکامرس و باسلام: from n/a through <= 1.9.1.

    Published: 13 Jul 2026
    7.6
    High

    CVE-2026-61955

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-59523

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.

    Published: 13 Jul 2026
    4.9
    Medium

    CVE-2026-61952

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.

    Published: 13 Jul 2026
    7.2
    High

    CVE-2026-59521

    Last Modified: 13 Jul 2026

    Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.

    Published: 13 Jul 2026
    9.8
    Critical

    CVE-2026-59518

    Last Modified: 13 Jul 2026

    Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-59516

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.

    Published: 13 Jul 2026
    9.3
    Critical

    CVE-2026-59515

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57816

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Funnel Builder by FunnelKit funnel-builder allows Reflected XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.15.0.8.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57815

    Last Modified: 13 Jul 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57814

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through <= 1.55.0.1.

    Published: 13 Jul 2026
    9.8
    Critical

    CVE-2026-57813

    Last Modified: 13 Jul 2026

    Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57812

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4.

    Published: 13 Jul 2026
    10
    Critical

    CVE-2026-57811

    Last Modified: 13 Jul 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.

    Published: 13 Jul 2026
    8.5
    High

    CVE-2026-57810

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57805

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Tonda tonda allows PHP Local File Inclusion.This issue affects Tonda: from n/a through <= 2.5.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57804

    Last Modified: 14 Aug 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57803

    Last Modified: 11 Aug 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core allows PHP Local File Inclusion. This issue affects Struktur Core: from n/a before 2.7.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57802

    Last Modified: 11 Aug 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur allows PHP Local File Inclusion. This issue affects Struktur: from n/a before 2.7.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57801

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 2.1.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57800

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.5.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57799

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue affects Nuss: from n/a through <= 1.3.6.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57798

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.

    Published: 13 Jul 2026
    4.3
    Medium

    CVE-2026-57797

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in ThemeMove EduMall edumall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduMall: from n/a through <= 4.5.1.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57796

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57795

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion.This issue affects Kitchor: from n/a through <= 1.4.3.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57794

    Last Modified: 27 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57793

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through <= 1.8.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57792

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.1.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57791

    Last Modified: 13 Jul 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0.

    Published: 13 Jul 2026